assets/27004-system-bypass-fqdns.json

{
  "metadata": {
    "description": "System bypass FQDN destinations for TLS inspection. These FQDNs are automatically excluded from TLS inspection by Global Secure Access due to known incompatibilities (certificate pinning, mutual TLS, etc.).",
    "specId": "27004",
    "lastUpdated": "2026-02-20",
    "sourceNote": "Provided by GSA backend team. API does not currently expose these FQDNs programmatically. This file must be manually maintained until a dedicated API endpoint is available.",
    "faqReference": "https://learn.microsoft.com/en-us/entra/global-secure-access/faq-transport-layer-security#what-destinations-are-included-in-the-system-bypass",
    "totalCount": 100
  },
  "fqdns": [
    "*.albert.apple.com",
    "*.appleid.apple.com",
    "*.apps.apple.com",
    "*.appstoreconnect.apple.com",
    "*.britishairways.*",
    "*.centanet.com",
    "*.cloud.microsoft",
    "*.docusign.net",
    "*.dropbox.com",
    "*.edgediagnostic.globalsecureaccess.microsoft.com",
    "*.eszigno.hu",
    "*.eszigno.microsigner.com",
    "*.gs.apple.com",
    "*.icloud.com",
    "*.idmsa.apple.com",
    "*.itunes.apple.com",
    "*.mail.protection.outlook.com",
    "*.mediatek.com",
    "*.metrics.apple.com",
    "*.microsoft.com",
    "*.microsoftonline.com",
    "*.microsoftonline-p.com",
    "*.mx.microsoft",
    "*.mzstatic.com",
    "*.ninjarmm.com",
    "*.office.com",
    "*.office.net",
    "*.office365.com",
    "*.officeapps.live.com",
    "*.outlook.com",
    "*.prod.microsoftmetrics.com",
    "*.prod.monitoring.core.windows.net",
    "*.prod.warm.ingest.monitor.core.windows.net",
    "*.protection.outlook.com",
    "*.setup.icloud.com",
    "*.sharepoint.com",
    "*.sharepoint-df.com",
    "*.signal.org",
    "*.store.apple.com",
    "*.teams.microsoft.com",
    "*.teamviewer.com",
    "*.webex.com",
    "*.whatsapp.com",
    "*.whatsapp.net",
    "*.windowsupdate.com",
    "*.xs.apple.com",
    "*.zdxcloud.net",
    "*.zoom.us",
    "*.zscalerbeta.net",
    "*.zscalertwo.net",
    "a.nel.cloudflare.com",
    "agent.sega.production.snap.bpcyber.com",
    "agent.siem.production.snap.bpcyber.com",
    "api.cloudflareclient.com",
    "app-site-association.cdn-apple.com",
    "app-site-association.networking.apple",
    "apple.com",
    "auto-load-balancer.likr.com.tw",
    "chime-ui-pov.ukpowernetworks.co.uk",
    "cmgtscen.totalizator.pl",
    "config.edge.skype.com",
    "crs.cr.adobe.com",
    "dc.services.visualstudio.com",
    "device-agent.app.us.guardz.com",
    "docusign.net",
    "dpmupdates.indilogic.com",
    "e-order2.centralplaza.com.hk",
    "e-szigno.hu",
    "eszigno.microsigner.com",
    "euiothubuniflow.azure-devices.net",
    "ewlistener.fp.wan.azure.com",
    "fpgw01.weareams.com",
    "graph.windows.net",
    "hpacmgprod.westeurope.cloudapp.azure.com",
    "icloud.com",
    "in.appcenter.ms",
    "init.ess.apple.com",
    "init.push.apple.com",
    "ios.chat.openai.com",
    "login-a-moje.o2.cz",
    "login.chinacloudapi.cn",
    "login.microsoftonline.us",
    "login.partner.microsoftonline.cn",
    "login.windows.net",
    "management.azure.com",
    "ndes.bluehawk.ch",
    "ngep.blackspider.com",
    "openspacesolutions.com",
    "pbiexa.powerbi.com",
    "pds-init.ess.apple.com",
    "production.diagnostics.monitoring.core.windows.net",
    "proxy.prod.pac.swg.umbrella.com",
    "signal.org",
    "spectrum.corp.adobe.com",
    "sts.windows.net",
    "testflight.apple.com",
    "ucc-regions.apluspc.ca",
    "vi8638.ci.managedwhitelisting.com",
    "webex.com",
    "zoom.us"
  ]
}